Avmirror.com is a rogue website that promotes the fake security program called Antivir Solution Pro. It restricts the browsing scope and affects the web-surfing destination. It hijacks your browser and displays scary program of high severity scale. It changes your browser settings and affects HOSTS file in such a manner that you will no longer be able to visit any other site except Avmirror.com. It is so because Antivir Solution Pro modifies your system registry entries. It enters into your computer via Trojans and stays inside your computer for a longer period.
It also produces a bogus Internet Warning asking for your actions to remove the infection from your computer. If you perform any activity then you are redirected to the Avmirror.com where you are supposed to purchase their product to remove the malware. You could not rescue from them until you purchase their program.
However if you are one of those who has already visited this website and are fiddling around for a solution to remove it from your computer then just follow the below steps.
1. Delete "%Documents and Settings%\[UserName]\Local Settings\Application Data\[random string]\[random string].exe" file.
2. Delete the below registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\PhishingFilter “Enabled” = “0“
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download “RunInvalidSignatures” =”1″
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “ProxyOverride” = ““
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “ProxyServer” = “http=127.0.0.1:5643″
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “ProxyEnable” = “1“
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations “LowRiskFileTypes” = “.exe”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments “SaveZoneInformation” = “1″
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “[random string]“
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run “[random string]“